(19)
(11) EP 2 905 715 A1

(12) EUROPEAN PATENT APPLICATION
published in accordance with Art. 153(4) EPC

(43) Date of publication:
12.08.2015 Bulletin 2015/33

(21) Application number: 13800249.8

(22) Date of filing: 22.07.2013
(51) International Patent Classification (IPC): 
G06F 21/34(2013.01)
(86) International application number:
PCT/CN2013/079782
(87) International publication number:
WO 2013/182154 (12.12.2013 Gazette 2013/50)
(84) Designated Contracting States:
AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR
Designated Extension States:
BA ME

(30) Priority: 17.10.2012 CN 201210395287

(71) Applicant: ZTE Corporation
Shenzhen, Guangdong 518057 (CN)

(72) Inventor:
  • LI, Xipeng
    Shenzhen Guangdong 518057 (CN)

(74) Representative: Jones, Cerian 
Urquhart-Dykes & Lord LLP 7th Floor, Churchill House Churchill Way
Cardiff CF10 2HH
Cardiff CF10 2HH (GB)

   


(54) METHOD, SYSTEM AND TERMINAL FOR ENCRYPTING/DECRYPTING APPLICATION PROGRAM ON COMMUNICATION TERMINAL


(57) A method, system and terminal for encrypting and decrypting an application program on a communication terminal are disclosed, including: the communication terminal using an identification number of a subscriber identification card as an encryption key, performing encryption processing on an application program to be protected, and obtaining an encrypted application program; when a user accesses the encrypted application program, the communication terminal performing matching processing on an identification number of a subscriber identification card inserted currently and the encryption key; and if a processing result is that the identification number of the subscriber identification card inserted currently is matched with the encryption key, performing decryption processing on the encrypted application program for the user to use. By encrypting an application program installed in the terminal through a key in the subscriber identification card, the user can freely select an application required to be encrypted in the terminal, which enhances the security of the application program in the terminal when accessed and used without influencing the access experience of the user for programs with low security requirements, and enhances the security of private data of the user in the terminal without losing good user experience.




Description

Technical Field



[0001] The present invention relates to the field of communication terminal technology, and specifically, to a method, system and terminal for encrypting and decrypting an application program through a key of a subscriber identification card.

Background of the Related Art



[0002] With the rapid development of smartphone terminals in recent years, the mainstream smartphones all support a subscriber identification card at present and they can download and install a great many application programs from the application market, but users do not have particularly effective protection measures on the access of the application programs installed in mobile phones at present, once others get your mobile phone, they can randomly check the application programs installed and the privacy information left in the mobile phone, such as mobile banking information and QQ account information and so on, that is, there exists a higher risk for the access and use of the application programs of the smartphones.

[0003] For terminals of the smart mobile type, the installation of application programs is very common, and a great deal of privacy information of the users is therein saved, thus it shows a trend of increasing data security problems. How to improve the security of application programs and user privacy information related to the application programs in the terminals of smart mobile type becomes a very important new subject, and there has been no mature scheme in the industry at present. The patent with an application number of CN201120101853.6 discloses a method for encrypting a TF card, and the scheme implements a method for encrypting a TF storage card on the whole, but it does not support the protection for the specific application programs installed in the communication terminal and the user information related to the application programs.

Summary of the Invention



[0004] The object of the embodiments of the present invention is to provide a method, system and terminal for encrypting and decrypting an application program on a communication terminal, and the terminal performs permission authentication through a Personal Identification Number (PIN) code, and performs encryption and decryption operation on the application program by using an identification number of a subscriber identification card.

[0005] The embodiment of the present invention provides a method for encrypting and decrypting an application program on a communication terminal, which comprises:

the communication terminal using an identification number of a subscriber identification card as an encryption key, performing encryption processing on an application program to be protected, and obtaining an encrypted application program;

when a user accesses the encrypted application program, the communication terminal performing matching processing on an identification number of a subscriber identification card inserted currently and the encryption key; and

if a processing result is that the identification number of the subscriber identification card inserted currently is matched with the encryption key, performing decryption processing on the encrypted application program for the user to use.



[0006] Alternatively, the method further comprises: before performing encryption processing on the application program to be protected, the communication terminal prompting the user to enter a subscriber identification card password, and sending a password authentication request containing the subscriber identification card password to the subscriber identification card;
the communication terminal receiving an authentication result returned by the subscriber identification card, and if the authentication is successful, acquiring the identification number of the subscriber identification card used as the encryption key.

[0007] Alternatively, after the encryption processing is performed on the application program to be protected, encryption state information of the encrypted application program is saved, wherein the encryption state information comprises the encryption key.

[0008] Alternatively, after the decryption processing is performed on the encrypted application program, the communication terminal extracts the subscriber identification card password entered by the user, and sends a password authentication request containing the subscriber identification card password to the subscriber identification card;
a password authentication response of the subscriber identification card is received, if the authentication is successful, making the user access and use the application program.

[0009] Alternatively, the subscriber identification card comprises a SIM card, a USIM card and a UIM card;
alternatively, the identification number of the subscriber identification card comprises an international mobile subscriber identification number IMSI and an integrated circuit card identity ICCID;
alternatively, the subscriber identification card password comprises an ADM code, a PIN1 code and a PIN2 code.

[0010] The embodiment of the present invention provides a system for encrypting and decrypting an application program on a communication terminal, which comprises:

an encryption module, configured to: use an identification number of a subscriber identification card as an encryption key, perform encryption processing on an application program to be protected, and obtain an encrypted application program; and

a decryption module, configured to: when a user accesses the encrypted application program, perform matching processing on an identification number of a subscriber identification card inserted currently and the encryption key, and if a processing result is that the identification number of the subscriber identification card inserted currently is matched with the encryption key, perform decryption processing on the encrypted application program for the user to use.



[0011] Alternatively, a subscriber identification card password authentication module is further configured to: before performing encryption processing on the application program to be protected, extract a subscriber identification card password entered by the user, send a password authentication request containing the subscriber identification card password to the subscriber identification card, and receive a password authentication response of the subscriber identification card responding to the request, and if the authentication is successful, acquire the identification number of the subscriber identification card used as the encryption key.

[0012] Alternatively, the subscriber identification card password authentication module is further configured to: after performing decryption processing on the encrypted application program, extract the subscriber identification card password entered by the user, send a password authentication request containing the subscriber identification card password to the subscriber identification card, and receive a password authentication response of the subscriber identification card responding to the request, and if the authentication is successful, make the user access and use the application program.

[0013] Alternatively, a storage module is configured to: after performing encryption processing on the application program to be protected, save encryption state information of the encrypted application program, wherein the encryption state information comprises the encryption key.

[0014] The embodiment of the present invention provides a terminal for encrypting and decrypting an application program on a communication terminal, which comprises the above system.

[0015] Compared with the related art, the beneficial effects of the embodiments of the present invention lie in that:

in the embodiments of the present invention, by encrypting an application program installed in a terminal through a key in a subscriber identification card, a user can freely select an application required to be encrypted in the terminal, which enhances the security of the application program in the terminal when being accessed and used without influencing the access experience of the user for programs with low security requirements, and enhances the security of private data of the user in the terminal without losing good user experience.


Brief Description of Drawings



[0016] 

FIG. 1 is a structural schematic diagram of a system for encrypting an application program on a communication terminal provided in the embodiment of the present invention.

FIG. 2 is a flow diagram of a processing method for a communication terminal encrypting an application program provided in the embodiment of the present invention.

FIG. 3 is a flow diagram of a processing method when a user accesses an application program provided in the embodiment of the present invention.


Preferred Embodiments of the Invention



[0017] The embodiments of the present invention will be described in detail below in combination with the accompanying drawings. It should be understood that, the descriptions below are only used to explain and illustrate the present invention, which is not used to limit the present invention.

FIG. 1 shows a structural schematic diagram of a system for encrypting an application program on a communication terminal provided in the embodiment of the present invention, which includes a subscriber identification card, application programs and a terminal. The application programs are installed in the terminal, and when a user uses the application programs, privacy information will be generated sometimes. FIG. 1 shows a relation diagram between the terminal and the subscriber identification card (i.e. an SIM card), before used for accessing the installed application programs, the terminal and the SIM card are required to go through an authentication operation process, and after the process ends, the SIM card returns an authentication result to the terminal: authentication is successful or authentication is failed.

FIG. 2 is a flow diagram of a processing method for a communication terminal encrypting an application program provided in the embodiment of the present invention, and as shown in FIG. 2, the encryption process includes that:

an implementation way of the application encryption entry mode is not unique, and it is assumed that the implementation way is entering through an application encryption menu of the terminal in the present document. The user enters the application encryption menu through an interactive menu of the terminal, and the related background programs will be started to perform relevant processing through selection operations of the menu.



[0018] We assume that the menu lists the application programs which have been installed in the current terminal at this point, and the user selects an application program required to be encrypted, and the terminal displays a prompt box at this point, to prompt the user to enter a PIN code of the SIM card.

[0019] After the user enters the PIN code, the terminal extracts PIN code information entered by the user, applies to the SIM card for PIN code authentication, and if the authentication is successful, the terminal extracts an identification number of the subscriber identification card in the SIM card to serve as a key and performs encryption operation on the application program. After the encryption is finished, encryption state information of the application program is recorded and saved, and the encryption state information includes the encryption key, which is used as a basis for processing and judging when the user accesses the application program next time. If a result of failed PIN code authentication is returned, the encryption operation fails.

[0020] FIG. 3 is a flow diagram of a processing method when a user accesses an application program provided in the embodiment of the present invention, and as shown in FIG. 3, the decryption process includes that:

when the user accesses an application program in the terminal, firstly the terminal judges an access permission of the application program, and if the application program has been encrypted, the terminal will proceed to the next processing process.



[0021] The terminal extracts a key used during the encryption from the application program, and the key is the identification number of the SIM card in the terminal when the application program is encrypted. Meanwhile, the terminal will read a subscriber identification number of an SIM card inserted into the terminal at this moment, compare the key with the subscriber identification number and judge whether the key and the subscriber identification number are consistent, if they are consistent, proceeding to the next processing process. If the key and the subscriber identification number are inconsistent, the authentication is failed, and the user cannot access and use the application program.

[0022] Following the last step, when the authentication is passed, the terminal will prompt the user to enter a valid PIN code at this point, and after the user enters the PIN code, the terminal extracts the PIN code information and then applies to the SIM card for PIN code authentication. If a returned authentication result is success, the user can normally access and use the application program. Otherwise, the user cannot access and use the application program.

[0023] In the embodiments of the present invention, the subscriber identification card includes but is not limited to: a SIM card and a UIM card and so on, cards belonging to the subscriber identification card are all within the protection scope of the present patent.

[0024] In the embodiments of the present invention, the function of the identification number of the subscriber identification card is to establish an association relationship between a specific application program in the terminal and a SIM card in the terminal during the encryption, and a function thereof is to guarantee a unique binding relation between the SIM card and the application program, that is, if the user changes to other SIM cards, the application program cannot be decrypted.

[0025] In the embodiments of the present invention, all information that can be read from the SIM card and can reflect the uniqueness of the SIM card, namely the identification number of the subscriber identification card, is within the protection scope of the present patent application. The identification number of the subscriber identification card includes an International Mobile Subscriber Identification Number (IMSI) and an Integrated Circuit Card Identity (ICCID) and so on.

[0026] The terminal supports the subscriber identification card such as the SIM card. The subscriber identification card includes but is not limited to: a SIM card, a USIM card and a UIM card and so on, cards belonging to the subscriber identification card are all within the protection scope of the present patent.

[0027] A password is saved in the subscriber identification card, and if the user knows an initial password, the password can be changed. The key in the subscriber identification card includes but is not limited to: an ADM code, a PIN1 code and a PIN2 code and so on, and passwords that can be used for implementing the method of the present invention are all within the protection scope.

[0028] The embodiment of the present invention also discloses a terminal, which includes the above system for encrypting the application program by using the key of the subscriber identification card. The terminal includes a mobile terminal and a fixed terminal.

[0029] In conclusion, the embodiments of the present invention have the following technical effects.

[0030] In the embodiments of the present invention, by encrypting an application program installed in a terminal through a key in a subscriber identification card, a user can freely select an application required to be encrypted in the terminal, which enhances the security of the application program in the terminal when accessed and used without influencing the access experience of the user for programs with low security requirements and enhances the security of private data of the user in the terminal without losing good user experience.

[0031] Though the embodiments of the present invention have been described in detail above, but the present invention is not limited to this, and the skilled in the art can make various modifications according to the principle of the present invention. Therefore, it should be understood that all the modifications made according to the principle of the present invention fall into the protection scope of the present invention.

Industrial Applicability



[0032] In the embodiments of the present invention, by encrypting an application program installed in a terminal through a key in a subscriber identification card, a user can freely select an application required to be encrypted in the terminal, which enhances the security of the application program in the terminal when accessed and used without influencing the access experience of the user for programs with low security requirements and enhances the security of private data of the user in the terminal without losing good user experience.


Claims

1. A method for encrypting and decrypting an application program on a communication terminal, comprising:

the communication terminal using an identification number of a subscriber identification card as an encryption key, performing encryption processing on an application program to be protected, and obtaining an encrypted application program;

when a user accesses the encrypted application program, the communication terminal performing matching processing on an identification number of a subscriber identification card inserted currently and the encryption key;

if a processing result is that the identification number of the subscriber identification card inserted currently is matched with the encryption key, performing decryption processing on the encrypted application program.


 
2. The method according to claim 1, further comprising:

before performing encryption processing on the application program to be protected, the communication terminal prompting a user to enter a subscriber identification card password, and sending a password authentication request containing the subscriber identification card password to the subscriber identification card;

the communication terminal receiving an authentication result returned by the subscriber identification card, and if the authentication is successful, acquiring the identification number of the subscriber identification card used as the encryption key.


 
3. The method according to claim 2, further comprising:

after performing encryption processing on the application program to be protected, saving encryption state information of the encrypted application program, wherein the encryption state information comprises the encryption key.


 
4. The method according to claim 3, further comprising:

after performing decryption processing on the encrypted application program, the communication terminal prompting a user to enter a subscriber identification card password, and sending a password authentication request containing the subscriber identification card password to the subscriber identification card;

the communication terminal receiving an authentication result returned by the subscriber identification card, and if the authentication is successful, making the user access and use the application program.


 
5. The method according to any one of claims 1 to 4, wherein
the subscriber identification card comprises a SIM card, a USIM card and a UIM card;
the identification number of the subscriber identification card comprises an international mobile subscriber identification number IMSI and an integrated circuit card identity ICCID;
the subscriber identification card password comprises an ADM code, a PIN1 code and a PIN2 code.
 
6. A system for encrypting and decrypting an application program on a communication terminal, comprising:

an encryption module, configured to: use an identification number of a subscriber identification card as an encryption key, perform encryption processing on an application program to be protected, and obtain an encrypted application program; and

a decryption module, configured to: when a user accesses the encrypted application program, perform matching processing on an identification number of a subscriber identification card inserted currently and the encryption key, and if a processing result is that the identification number of the subscriber identification card inserted currently is matched with the encryption key, perform decryption processing on the encrypted application program.


 
7. The system according to claim 6,
a subscriber identification card password authentication module, configured to: before performing encryption processing on the application program to be protected, extract a subscriber identification card password entered by a user, send a password authentication request containing the subscriber identification card password to the subscriber identification card, and receive a password authentication response of the subscriber identification card responding to the request, and if the authentication is successful, acquire the identification number of the subscriber identification card used as the encryption key.
 
8. The system according to claim 7,
the subscriber identification card password authentication module is further configured to: after performing decryption processing on the encrypted application program, extract a subscriber identification card password entered by a user, send a password authentication request containing the subscriber identification card password to the subscriber identification card, and receive a password authentication response of the subscriber identification card responding to the request, and if the authentication is successful, make the user access and use the application program.
 
9. The system according to any one of claims 6 to 8, further comprising:

a storage module, configured to: after performing encryption processing on the application program to be protected, save encryption state information of the encrypted application program, wherein the encryption state information comprises the encryption key.


 
10. A terminal for encrypting and decrypting an application program on a communication terminal, comprising the system according to any one of claims 6 to 9.
 




Drawing










Search report










Cited references

REFERENCES CITED IN THE DESCRIPTION



This list of references cited by the applicant is for the reader's convenience only. It does not form part of the European patent document. Even though great care has been taken in compiling the references, errors or omissions cannot be excluded and the EPO disclaims all liability in this regard.

Patent documents cited in the description